SUSPICIOUS — 9975996148.pdf
SUSPICIOUS — 9975996148.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ba2323bc7e3221d739e32137598a4745399bac9d1d8f93741917a3520b745591 - SHA-1:
0ef88a665b301b509d93fd9b4454bab14355b8f8 - MD5:
f57d0db9a9d45f3ef913b45916cff189 - ssdeep:
768:3gGzpD0kPB+Jv4/1gdq6eQ2Sxax62fUT2r+kSI9+QJDjZ9IPLnCVWre9f:QGFwkPrt6DFxzT2rxpjYLngYe9f - TLSH:
T1B933AEF34057FCCC7B8AAB0759B710AA6546C78D3132AA6458C87B6CC47C6FD2E14A50 - Submitted as: 9975996148.pdf
- File type: pdf · Size: 49960 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=seat+arona+price+list+pdf, https://uploads.strikinglycdn.com/files/2e0fea0b-9c5c-442d-b798-d0b16c1354f6/464015861.pdf, https://uploads.strikinglycdn.com/files/4b61e57b-2cb5-4d9c-85af-adef21349e5f/21969402328.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=seat+arona+price+list+pdf
- https://uploads.strikinglycdn.com/files/2e0fea0b-9c5c-442d-b798-d0b16c1354f6/464015861.pdf
- https://uploads.strikinglycdn.com/files/4b61e57b-2cb5-4d9c-85af-adef21349e5f/21969402328.pdf
- https://uploads.strikinglycdn.com/files/3af586b9-86dd-4d13-a997-bb4219fb1f0c/gogabiriwolixesufer.pdf
- https://cdn.shopify.com/s/files/1/0434/6668/6617/files/38974084315.pdf
- https://cdn.shopify.com/s/files/1/0479/3709/3788/files/strength_to_love_martin_luther_king_free_download.pdf
- https://cdn.shopify.com/s/files/1/0438/3594/9218/files/mists_of_akuma.pdf
- https://site-1038423.mozfiles.com/files/1038423/waroxuresus.pdf
- https://site-1038675.mozfiles.com/files/1038675/mitofonizivebejiditunema.pdf
- http://govamam.interdynartis.com/uploads/1/3/1/4/131437502/xepeduwipo.pdf
- http://vowibu.vigtools.com/uploads/1/3/1/3/131379699/9259675.pdf
- http://befovu.dralisonpt.com/uploads/1/3/1/4/131406352/4de741ef8.pdf
- http://files.skylooker.org/uploads/1/3/0/7/130739084/97c9bce9.pdf
- http://files.gaynorhollisacupuncture.com/uploads/1/3/0/7/130775734/2037166.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1038423.mozfiles.com
- site-1038675.mozfiles.com
- govamam.interdynartis.com
- vowibu.vigtools.com
- befovu.dralisonpt.com
- files.skylooker.org
- files.gaynorhollisacupuncture.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report